Lucene search

K
ibmIBM7CE8633CD0C1791A2DB0393389C52B4DA138C2B4CE5CD446236FE8D31BE99299
HistoryJan 29, 2024 - 9:30 p.m.

Security Bulletin: IBM Maximo Asset Management could allow a remote attacker to bypass authentication due to improper access controls (CVE-2023-32333)

2024-01-2921:30:06
www.ibm.com
35
ibm maximo asset management
remote attacker
authentication bypass
improper access controls
cve-2023-32333
security bulletin
vulnerability
fix
user registration group

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

6.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

38.0%

Summary

IBM Maximo Asset Management could allow a remote attacker to bypass authentication due to improper access controls (CVE-2023-32333). This only impacts environments using native Maximo security when security options have been incorrectly applied to the MAXREG user.

Vulnerability Details

CVEID:CVE-2023-32333
**DESCRIPTION:**IBM Maximo Asset Management could allow a remote attacker to log into the admin panel due to improper access controls.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/255073 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)

Affected Products and Versions

Product versions affected:

Affected Product(s) Version(s)
IBM Maximo Asset Management 7.6.1.3
  • To determine the core product version, log in and view System Information. The core product version is the β€œTivoli’s process automation engine” version. Please consult the Platform Matrix for a list of supported product combinations.

Remediation/Fixes

The recommended solution is to download the appropriate Interim Fix or Fix Pack from Fix Central and apply for each affected product as soon as possible. Please see below for information on the fixes available for each product, version, and release. Follow the installation instructions in the β€˜readme’ documentation provided with each fix pack or interim fix.

For Maximo Asset Management 7.6:

VRM Fix Pack, Feature Pack, or Interim Fix Download
7.6.1.3

Maximo Asset Management 7.6.1.3 iFix:

7.6.1.3-TIV-MBS-IF012 or latest Interim Fix available

|

FixCentral

Additional manual steps are required to ensure the issue is resolved. See the**Workarounds and Mitigations **section.

Workarounds and Mitigations

Note: In the instructions below, the names for the Self-Registration and Everyone groups vary by installation. If you are unsure of the actual group name, look it up as follows:

  • The mxe.system.reguser property determines the User Registration group name.
  • The ALLUSERGROUP MAXVAR determines the Everyone group name.

Ensure that the following security privileges are correctly configured:

1. The MAXREG user must only belong to the User Registration group. To confirm:

  1. Go to Users and open MAXREG.
  2. On the Groups tab, remove all groups except the User Registration group.

Note: The Everyone group cannot be removed from the UI and must be deleted directly in the database if needed. This is only required if this group has been granted specific application access (which is not recommended).

2. The User Registration group must only have access to the applications SELFREG and FORGOTPSWD. To confirm:

  1. On the Security Profile tab in the Users application, verify that MAXREG only has application access for Self Registration and Forgot Password.
  2. If there are additional applications listed, revoke them from the User Registration group.

This can also be achieved by executing the following query to check for any incorrect permissions:

select * from applicationauth where groupname = <user registration group> and app not in (β€˜SELFREG’,β€˜FORGOTPSWD’)

If any are present, they can be revoked as follows:

delete from applicationauth where groupname = <user registration group> and app not in (β€˜SELFREG’,β€˜FORGOTPSWD’)

Affected configurations

Vulners
Node
ibmmaximo_asset_managementMatch7.6.1
CPENameOperatorVersion
ibm maximo asset managementeq7.6.1

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

6.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

38.0%

Related for 7CE8633CD0C1791A2DB0393389C52B4DA138C2B4CE5CD446236FE8D31BE99299